Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Reader_helper' = '%CommonProgramFiles%\Adobe\reader_helper.exe s'
- <SYSTEM32>\svchost.exe
- %TEMP%\1.tmp
- 'wa####.mrface.com':80
- '12#.#17.213.2':443
- '12#.#17.213.2':80
- 'my####.ftpserver.biz':443
- 'my####.ftpserver.biz':80
- 'wa####.mrface.com':443
- 12#.#17.213.2/View?id###################
- wa####.mrface.com/View?id###################
- my####.ftpserver.biz/View?id###################
- DNS ASK wa####.mrface.com
- DNS ASK my####.ftpserver.biz
- ClassName: 'Indicator' WindowName: ''